Skip to content
TRILOGY

WAF, API Protection & DDoS

Protect public applications and APIs from exploitation, bots and denial-of-service.

When this becomes relevant

New public portal or API. Bot or credential-stuffing attack.

  • WAF policy (positive/negative models)

  • API discovery and schema enforcement

  • Bot management

  • L3–L7 DDoS mitigation

Technologies we implement

We select the platform against your requirement, existing estate and support model — not the other way round.

  • Akamai
    • App & API Protector
  • Cloudflare
    • WAF
    • API Shield
  • F5
    • Distributed Cloud WAAP
  • Fastly
    • Next-Gen WAF
  • Imperva
    • WAAP
  • Radware
    • AppWall
    • DefensePro

Names and trademarks belong to their owners.

What you receive

  • Application inventory

  • Policy baseline

  • Tuning record

  • Test report

What we offer

01

Design & architecture

  • Sizing
  • High-level and low-level design
  • Bill of materials

02

Implementation & migration

  • Installation and configuration to the approved design
  • Migration waves and cutover
  • Tested rollback

03

Verification & handover

  • Test plans, results and sign-off
  • As-built documentation and runbooks
  • Knowledge transfer
  • WAF policy (positive/negative models)
  • API discovery and schema enforcement
  • Bot management
  • L3–L7 DDoS mitigation
  • Logging to SIEM
Two colleagues reviewing an architecture of boxes on a wall display

Capabilities in detail

WAF policy (positive/negative models)
What
WAF policy (positive/negative models)
How
Designed with your team, implemented in approved change windows and verified against the agreed scope before handover.
You receive
Application inventory
API discovery and schema enforcement
What
API discovery and schema enforcement
How
Designed with your team, implemented in approved change windows and verified against the agreed scope before handover.
You receive
Policy baseline
Bot management
What
Bot management
How
Designed with your team, implemented in approved change windows and verified against the agreed scope before handover.
You receive
Tuning record
L3–L7 DDoS mitigation
What
L3–L7 DDoS mitigation
How
Designed with your team, implemented in approved change windows and verified against the agreed scope before handover.
You receive
Test report
Logging to SIEM
What
Logging to SIEM
How
Designed with your team, implemented in approved change windows and verified against the agreed scope before handover.
You receive
Application inventory

Discuss your requirement

Prefer to talk? Call +966591909277

We use the information you provide to respond to your request. Read our privacy notice for details.